Security Engineer Internship
- Hiring from
- Worldwide
- Work type
- Remote
- Posted
- Sep 24, 2026
Security Engineer
Overview: Supply Chain Security and Compliance
The Security Engineer is a critical role responsible for implementing and enforcing robust security practices across our entire integrated supply chain e-commerce platform. You will safeguard e-commerce transactions, secure internal tool integrations, and establish the trust framework for our AI agent operations, ensuring compliance with global regulatory standards like PCI-DSS and GDPR.
Internship Details
Duration: 3 months (extendable based on performance and project scope)
Start Date: Immediate
Location: Remote
Stipend: Unpaid initially; may convert to a paid internship, full-time role, or even direct client absorption (FTE) based on your performance
Key Responsibilities & Core Projects
You will secure all layers of the application, from the Next.js frontend to the NestJS modular monolith and the cloud infrastructure.
Security Architecture & Threat Modeling: Perform vulnerability assessments, code reviews, and threat modeling for all new features and systems, focusing on the critical MES $\rightarrow$ WMS $\rightarrow$ OMS business process flow.
Compliance Enforcement: Lead the implementation and auditing of security controls necessary for PCI-DSS compliance (for Payment module) and GDPR compliance (for user/tenant data handling).
Access Control & Authentication: Implement and manage secure API authentication methods, including OAuth 2.0 and SAML, utilizing Authentik/Ory Kratos and leveraging PostgreSQL's Row-Level Security (RLS) for tenant isolation.
Secrets & Encryption: Manage secrets and key rotation using Vault, define and enforce encryption protocols for data both in transit and at rest, and manage certificates via Traefik.
Abuse Prevention: Implement and monitor controls for API rate limiting, Web Application Firewall (WAF) rules, and traffic monitoring to prevent abuse and denial-of-service attacks.
Incident Response: Develop and practice incident investigation and response protocols. Conduct security awareness training for development and operations teams.
Required Technologies & Tools
Candidates must possess hands-on security experience with our core stack and compliance tools:
Platform Security: Node.js/NestJS security best practices, Next.js/React security, PostgreSQL RLS.
Compliance Focus: Experience with PCI-DSS and GDPR controls and auditing.
Authentication & Access: OAuth 2.0, SAML, JWT, Authentik/Ory Kratos.
Secrets & Infrastructure: HashiCorp Vault, Docker, Terraform.
Monitoring & Assessment: Tools for Static/Dynamic Application Security Testing (SAST/DAST).
AI Agent Security
You will be responsible for securing the emerging AI ecosystem.
Agent Trust Framework: Establish security boundaries for the AI agent interfaces, ensuring agents (built with LangChain/AutoGen) operate within strict permissions when accessing supply chain data (WMS, OMS).
Prompt Injection Prevention: Implement validation and sanitization techniques to mitigate prompt injection and data exfiltration risks in user-facing LLM interactions.
Success Metrics & Career Path
Performance will be measured by:
Security Scorecard: Reduction in identified vulnerabilities from assessments and code reviews (SAST/DAST).
Compliance Audits: Successful passing of regular PCI-DSS and GDPR audits.
Incident Handling: Speed and effectiveness of security incident investigation and remediation.
Mentorship Structure: Reports to the Solution Architect or Head of Technology, working closely with the development and DevOps teams to embed security into the CI/CD pipeline.